AI-Powered Systems Can Automatically Discover Zero-Day Vulnerabilities at Scale
Researchers at Intruder demonstrated that combining AI large language models with program slicing techniques can fully automate the discovery of exploitable zero-day vulnerabilities, uncovering a multi-stage SQL injection flaw in a WordPress plugin used by over 300,000 sites — with no human intervention required. This matters because it fundamentally lowers the barrier to finding critical vulnerabilities: attackers no longer need elite human researchers when automated pipelines can do the work at scale and speed. Organizations relying on slow, manual patching cycles or infrequent vulnerability assessments are now dangerously exposed, as threat actors could weaponize similar AI tooling before defenders are even aware a flaw exists. The attack surface of widely deployed open-source plugins and third-party software is now under pressure from a new class of automated adversarial discovery.
Tactical Insight
Immediate actions
- Audit and update all third-party plugins, libraries, and dependencies to their latest patched versions, prioritizing high-install-count software.
- Subscribe to vulnerability disclosure feeds (e.g., WPScan, NVD, vendor advisories) to receive real-time alerts for software in your stack.
- Implement a Web Application Firewall (WAF) with SQL injection rules as a compensating control while patches are evaluated.
Long-term improvements
- Establish a formal Software Composition Analysis (SCA) process to continuously inventory and monitor third-party components for newly disclosed CVEs.
- Adopt a risk-based emergency patching SLA (e.g., critical vulnerabilities patched within 24–72 hours) and enforce it through change management procedures.
- Integrate static analysis and AI-assisted code review tools into your SDLC to proactively surface injection flaws before code reaches production.
Detection measures
- Deploy database activity monitoring (DAM) and query anomaly detection to identify unusual or malformed SQL patterns indicative of injection attempts.
- Enable centralized logging of all application errors and database exceptions, and alert on anomalous query structures or elevated error rates.
- Conduct regular penetration tests and red team exercises that include automated AI-assisted scanning to match the capabilities of modern adversaries.